
Is text messaging considered harassment?
Key Facts
- A single unwanted text can cost $500, rising to $1,500 per message for willful violations, per TCPA statutory rates.
- TCPA class actions filed through mid-2025 surged nearly 95% year-over-year, according to compliance analysis.
- A 100,000-message campaign sent without consent could exceed $150 million in class action exposure — there is no aggregate cap, per statutory damage rules.
- The FCC treats text messages as 'calls,' meaning SMS faces the same consent restrictions as phone calls, per FCC interpretation.
- Do-Not-Call Registry violations carry penalties of up to $43,792 per call or text, under federal rules.
- The FCC's 2024 rule closed the lead generator loophole, requiring one-seller-at-a-time consent, per the Federal Register.
- Connecticut's mini-TCPA law imposes penalties up to $20,000 per violation — one of roughly a dozen stricter state laws, per compliance research.
When a Text Message Crosses the Legal Line
A single unwanted text can cost your business $500. It sounds dramatic, but it is the literal statutory minimum under federal law — and the number only goes up from there.
Here is the direct answer: yes, unwanted text messages can cross a legal line, but not the one most people expect. The legal framework is the Telephone Consumer Protection Act (TCPA), which creates civil liability rather than criminal harassment charges. The FCC has long interpreted the TCPA to treat text messages as "calls," meaning SMS faces the same restrictions as phone calls, according to compliance analysis from Infobip.
The legal question hinges almost entirely on consent. Marketing texts require prior express written consent, while transactional messages require prior express consent. Consent must be obtained through an active, unchecked-by-default checkbox — buried disclaimer text does not qualify, and inferred or passive "implicit consent" does not meet TCPA requirements. Continuing to text after someone opts out is where harassment claims crystallize.
The financial exposure is severe and scales fast:
- $500 per message at the standard statutory rate, rising to $1,500 per message for willful or knowing violations
- No cap on aggregate damages — a 100,000-message campaign sent without consent could exceed $150 million in class action exposure
- TCPA class actions filed through mid-2025 were up nearly 95% year-over-year
- Do-Not-Call Registry violations carry penalties of up to $43,792 per call or text
There is no minimum threshold, either. Even one unauthorized message can trigger liability, as legal experts at Holland & Knight note — their litigation team observes that virtually any business contacting consumers under TCPA-covered technologies is at risk, with some plaintiffs alleging millions of violations.
The FCC's 2024 final rule tightened the screws further, extending Do-Not-Call protections to texts and closing the lead generator loophole by requiring one-seller-at-a-time consent.
This is why consent verification is the primary legal defense. A key litigation strategy involves proving consumers provided prior express consent — which is why My AI Call Center reviews list source and consent records before any campaign launches, and declines bought lists lacking clear permission documentation. Honoring opt-outs immediately and across all lists, not just the campaign someone replied to, completes the defense.
Why Consent Is the Whole Ballgame
Consent is the legal cornerstone that determines whether a text message is permissible contact or actionable harassment under the TCPA. Marketing texts require prior express written consent, while transactional or informational messages only need prior express consent. This distinction is not merely procedural — it defines liability exposure, with statutory damages ranging from $500 to $1,500 per unauthorized message and no cap on aggregate exposure in class actions.
Buried fine print, pre-checked boxes, or vague disclaimers do not satisfy either consent standard. Consent must be clear and conspicuous, obtained via an active, unchecked-by-default checkbox where the consumer knowingly and voluntarily agrees to receive automated texts from a specific brand. Implicit or inferred agreement fails to meet TCPA requirements, as confirmed by compliance guidance emphasizing that disclaimer text alone is insufficient for valid consent.
The FCC’s 2024 rule eliminating the lead generator loophole now mandates one-seller-at-a-time consent for marketing communications. Comparison shopping websites and similar platforms can no longer bundle or sell consumer consent across multiple brands; each sender must obtain its own direct, verifiable agreement. This change reinforces that consent cannot be shared, transferred, or assumed — it must be specific, current, and tied to the exact entity sending the message.
For organizations using managed outbound services like My AI Call Center, this means list discipline and consent verification are not optional best practices but legal necessities. Campaigns only launch after reviewing list sources and consent records, ensuring every contact has provided the appropriate level of permission for the message type being sent. Without this foundation, even well-intentioned outreach risks triggering TCPA violations that courts increasingly treat as harassment due to their repetitive, unwanted nature. Opt-out compliance further strengthens this defense — honoring STOP requests immediately and across all lists prevents the kind of continued contact that transforms non-compliance into liability. Ultimately, consent isn’t just a checkbox; it’s the entire framework that separates lawful engagement from actionable harm.
Where Harassment Claims Actually Crystallize: Opt-Outs, Quiet Hours, and State Laws
Most texts that end up in court started out perfectly legal. The lawsuit rarely comes from the first message — it comes from the fifth one, sent after a STOP request, at 10pm, in a state with stricter rules than the sender ever checked.
Opt-outs are where compliant becomes actionable. Continuing to message after a valid opt-out constitutes non-compliance and may support harassment claims, according to TCPA compliance guidance. The regulatory ceiling for processing is 10 business days, but best-practice guidance treats immediate processing as the standard — and opt-outs must apply to all marketing lists, not just the campaign the recipient replied to.
That last point trips up multi-location businesses constantly. A customer texts STOP to a promotion, then gets a reminder from a different division's list two weeks later. From their side, you ignored them twice. From a plaintiff's attorney's side, that is two violations at $500 to $1,500 per message, with no minimum threshold — even one unauthorized message can trigger liability.
Quiet hours are the second failure point. Texts must respect 8am–9pm in the recipient's local time zone, not the sender's. A campaign queued from one office time zone can land outside legal hours for recipients three zones away. After-hours messages should be held and released inside the window, not fired off because the queue was full.
Then there is the state layer. Roughly a dozen states have "mini-TCPA" laws that stack on top of federal rules, and where state law is stricter, it takes precedence:
- Texas — SMS added to the DTPA with a private right of action (September 2025)
- Florida — 15-day safe harbor, and no more than 3 messages per 24 hours
- Connecticut — written consent required, with penalties up to $20,000 per violation
- Virginia — opt-out records must be retained for 10 years (effective January 2026)
- Arizona — fines up to $1,000 for unsolicited texts to DNC-registered numbers
This is why list and consent review has to happen before launch, not after the first complaint. At My AI Call Center, list source, consent records, and calling windows are reviewed as a standard step before any campaign runs — because the operational details above are exactly what turn a permissioned contact into an actionable one. The FCC's 2024 rule also codified that Do-Not-Call Registry protections extend to text messages, so DNC status now needs the same checking for SMS that it always has for calls.
If you are planning outbound contact and want your list and consent records reviewed before you spend anything, explore managed campaigns — structured calling from 9¢ per connected minute, with opt-outs logged and honored immediately.
How to Verify a List Before You Text or Call Anyone
The cheapest time to catch a compliance problem is before the first message goes out. With TCPA statutory damages running $500 to $1,500 per message and no cap on aggregate liability, a flawed list can turn a routine campaign into a class action — litigation defense teams note that proving prior express consent is the primary shield, which makes pre-launch verification the most important step you can take.
Start with where the list came from. A bought list without clear permission records is a red flag, not a bargain. The FCC's 2024 rule closed the lead generator loophole by requiring consent to be given one seller at a time, and consent cannot be shared across brands or resold to third parties. If you cannot trace each contact back to a documented opt-in, the list will not support a compliant campaign.
Check the consent records themselves. Valid consent must be clear, conspicuous, and gathered through an active, unchecked-by-default checkbox — fine print and "implied" agreement do not count under TCPA requirements for SMS marketing. Marketing texts need prior express written consent, while transactional messages need only prior express consent, so the paperwork standard differs by message type.
Keep marketing and transactional content separate. Adding a promotional line to an appointment reminder reclassifies the entire message as marketing, raising the bar to written consent. One clear goal per message keeps you on the right side of that line.
Before any campaign launches, work through this checklist:
- Confirm the list source and how permission was originally obtained
- Verify consent records exist for each contact and match the message type
- Flag contacts in regulated states with mini-TCPA laws stricter than federal rules — roughly a dozen states qualify, including Connecticut with penalties up to $20,000 per violation
- Confirm calling windows respect 8am–9pm recipient local time
Treat AI-assisted messages as fully regulated. The FCC's February 2024 ruling confirmed that AI-generated voices count as artificial voices under federal law, and the same consent and disclosure requirements apply to AI-generated or AI-assisted SMS, according to compliance analysis of the ruling. There is no lighter rulebook because software drafted the message.
This is exactly why My AI Call Center reviews list source, consent records, and calling windows before any campaign launches, and tells you plainly if a list will not support the campaign — before you spend anything. Lists without clear permission records are flagged and, in most cases, declined. It is far less painful to hear "no" at the planning stage than to explain an unconsented campaign later.
Run Compliant Outbound Campaigns Without the Legal Guesswork
Run Compliant Outbound Campaigns Without the Legal Guesswork
Text messaging becomes legally actionable under the TCPA when sent without proper consent or after an opt-out request, creating real harassment-like exposure for businesses that overlook list discipline. The FCC treats SMS as equivalent to phone calls, meaning the same consent rules apply — marketing texts require prior express written consent, while informational messages need prior express consent. This legal framework turns consent verification into the frontline defense against costly violations, especially as TCPA class actions filed through mid-2025 rose nearly 95% year-over-year.
A managed, structured approach eliminates guesswork by enforcing consent verification at every stage. Campaigns launch only against approved, permissioned, or reviewed lists where consent records are checked and documented before any outreach begins. Bought lists lacking clear permission trails are flagged and typically declined, with clients informed upfront if the list won’t support compliant contact. This pre-launch review directly supports a key TCPA litigation defense: proving consumers provided prior express consent to receive messages.
Opt-out handling is where compliance is won or lost. Honoring opt-out requests immediately and logging them across all marketing lists — not just the campaign that triggered the reply — prevents the non-compliance that fuels harassment claims. Scripts, disclosure language, and escalation paths are approved before launch, ensuring recipients can easily opt out via keywords like STOP or natural-language intent, with AI systems designed to recognize and act on such signals without delay. Outcome reporting remains transparent, showing actual results like confirmed appointments, qualified leads, or logged opt-outs — never inventing metrics or client testimonials.
For multi-location organizations in healthcare, franchises, recruitment, or property services, this disciplined process turns outbound outreach into a reliable tool for confirmation, qualification, reminders, and retention — all while staying within TCPA boundaries. By anchoring campaigns in verified consent, real-time opt-out compliance, and honest reporting, businesses can reach the people who want to hear from them without crossing into legally risky territory. The result is outreach that’s not just effective, but demonstrably compliant from the first message to the last.
Frequently Asked Questions
Can a text message actually be considered harassment under the law?
How much can one unwanted text message cost my business?
Does a pre-checked box or fine print count as consent for texting?
What happens if someone texts STOP and I keep messaging them?
Do state laws make texting rules stricter than the federal TCPA?
Do AI-generated texts follow different rules than messages a person writes?
Turn Compliance into Your Competitive Edge
The line between helpful outreach and legal exposure in text messaging is thinner than most businesses realize — and it’s drawn not by intent, but by consent, timing, and opt-out discipline. As we’ve seen, a single unauthorized message can trigger $500 in statutory damages, with no cap on aggregate liability, and TCPA class actions are rising sharply. The good news? This risk is entirely manageable. By verifying consent records before launch, honoring opt-outs immediately across all lists, respecting quiet hours and state-specific rules, and treating every message — whether human- or AI-assisted — as fully regulated, you transform compliance from a burden into a business advantage. When your outreach is built on verified permission and transparent processes, you’re not just avoiding fines; you’re earning trust. If you want to run outbound campaigns that confirm, qualify, and connect — without the legal guesswork — explore managed campaigns at myaicallcenter.app/campaigns and start with a free list and consent review before you spend anything.